internet-explorer_11.0.exe

Rofasalota

Sivensys SRL

The executable internet-explorer_11.0.exe, “Rofasalota Setup ” has been detected as malware by 1 anti-virus scanner. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.funcentralnew.com and multiple other hosts.
Publisher:
Sivensys SRL  (signed and verified)

Product:
Rofasalota

Description:
Rofasalota Setup

Version:
2.8.1.7

MD5:
d19f9a163dab6ef88509dca5d3066b15

SHA-1:
600be243151c5f20d92f8c95d59f5ee00919bd7c

SHA-256:
01f46cb39e3b1a4395aa362bc2dfbc24aacdcdd5e0310a1336c2b033228fb0aa

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/14/2024 11:22:05 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.16.8

File size:
1.2 MB (1,292,528 bytes)

Product version:
4.3.7

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
10/20/2016 10:04:57 AM

Valid to:
10/21/2017 10:04:57 AM

Subject:
CN=Sivensys SRL, O=Sivensys SRL, L=IASI, C=RO

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE

Serial number:
0D38E905F0B0BA5733036DFB

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9855

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file internet-explorer_11.0.exe has been seen being distributed by the following 5 URLs.

http://www.funcentralnew.com/ N2JerRZax3aRuAGsnKIIcNhXcCGJuwBcBLB0tmCNI2j8l8g5X9vnplf7ud3btXloKKttY5kK1i4aAy4USg9rrBcRLUnTkPVi0D2zeINL duHFzSlswokkKb7zMZP3vP2m5Kpb 3lb5ikWwI3FykmS9Rp8yqU7a69voOnQ1 B_oAwRRS_5zw7h5a40hkyrn0ps3JZdGwlZqV58pd0UERblUxvMUJXMIzWQhmmckimFb0Glq 6ca2p_KJfcXuM3rmIlYMPOCeoJE gyn1b OO2vVYsrqw0siP 2m_qMBgzzLrTZFudLMIHLxadyf0tp048MiGJvhY0Z83UYDRQexVPhDl1O7IOcluOg2sE8XRK0S3rPLQwPF HovyTAahpn7Q8LCMT37cDw0YiKqOVMYYWcyD0l8VNdXWiWDxAeu61BsbkGfVJx7ZLLvFkbnZwvQKrwndciNlbTZwQWwFvyv eRRfK8efiQ==-GxQAAKRdxtretCCEFCKK5DqwG4Nvu_EA-e

http://www.funcentralnew.com/SFsdj61Lc5hc9en3uJzASGN7tG42LhL6wcvkST1WoAQEaC_iyDRfjSEphrKvD0f68CthZfasgPMoh6_OPNmsMuDmlrMANHelp3PI_UHVxu 1lh26A6zKNIf_0OBEZIScas8KZ7ddO6ONPse_1 oRo2omhlOGQbMKjJuIXNm8KEpbH0T_isio7dgTcLG1cE0rDn4YJUVPqh M1kDVBe7dafmgYrpNL0SmovHri3O8z5KalYohFmhAUGVUp9I9lhqRpq6pApgCTTpP7vB2oLa m8NlD3G0x36adZiQqArEtEwTbUnm7Ys9mhPLy6wuaN7SVxqEjn1NhHh84yADiLJ6F910V3xB7P4jLMkzWmoWURzx91tNTXXraFWICri3_kZSv08b3YMru9nk094QpGq5ZKGeoDjCdbBIiMi5xjwoO ZMGkbyKVtIQ8oL_tWWWsN9k7MXQTJcS9BEzMb1N0qM_qw4ay3egA==-GxQAAKRdxtretCCEFCKK5DqwG4Nvu_EA-e

http://www.funcentralnew.com/bVkx7C8zFS9tKsdQJ_t5Xd PbXtstThhdFLdMpF0H01Gwxi_FiQsdS8iBsEOwG35hK7y0HaMue_9rYuk3bi3l Dla9RuR3oxU_0iQOd_8LjsGFG5467sYbk4JJTtujpC6mmlx KNGkY4c5s0I3T CSgH7HSTaNbYSezLmxuCQDiQLWt02TgWW1WeI7TcI3ZzXnMFlJjcMJ1ITaEZxu0QM5h175YXpPNpx 5BhXsOEwjoJkIIfZjL4MvF a5Hnt1pM4GYheIaclz6KeDVEzhFw2O9OwR1qzAke3ChrHe6pqVUDHUqjEi4uHUZxBJnfUh78BH0ywjEJMWA4KzwGta 98zUphcwCH5bWHchwqiS2FWnGwCRersm_9twgwg9XX2L0V9ZC7QnhzEen81MN89T3UyOodbxGfmETPfSChQZoxWc Uyo39KrOSbY1RFR3zLCOJabzig2JyRI4vJ9JMnqSVLcPmOu1Q==-GxQAAKRdxtretCCEFCKK5DqwG4Nvu_EA-e

http://www.funcentralnew.com/v99vEug5IUSbbCDXJUDJIMxHkO0gOc_9S2Cq8FnxIbJC2UpQP9HLVBwSdSQxt2cPpf6yx8ilL6Z29bm4bqd7BJuhU9z_IltROlrWPhnsxG1dzwaNDovmnC5sjRf7Tt9JzIQhX_AxN2cBlDQh1Ahx1uDBe31DP4GYZzwcGM03S2ziqmQDTCBx94kXt4qo8DqxqrHjDjjsBaaXpI5dQCFCB78LecIe4VeJs_ixZSLywRy00ECtk6Z66TFfZNVXiLuX5hVFEfmcip696XzXyaZWVa7xZSFrKKRe8a5bu8ZTkWjFL9p ICi0bmL ABUnjtkuAvzVXXNbOkFiwSHUHfWyJFx7sODtOawDJBKSwaTCG2LHfCc rP4RRLDgrW1JHLR CFikjAI8zak1PI43M BMywFoXi3sq9EwJBWeA1jPdYTCZslUEoLCtlYv6MV0xoN44yRl7g Ol1nwGHZymgZyCZEabkzdqg==-GxQAAKRdxtretCCEFCKK5DqwG4Nvu_EA-e

http://www.funcentralnew.com/GkyFhdv3EeiF8B7cS8HF055DON0VHbWFHaGu_Gcuj4zqL5acscvIRMJZVrKpbxeBMShlhy_FNn8z7Kdblj1aweWjdkLPRXsCZG5AlFNwH0PE0ouynuhbtECp uLbtvRYmOat7MbuyaU7TOSe07LyIfVPhmU_PF8pftPFNbfNH85SQdTbg96_1W_6LirbXf1CcwDkQ4u8ChtrrJ3OR9YKGtgCqfnaIy8wu_i611SzTmyy4YVHcO8qw WxzOY3dH2irdxpxJxkz2Iwrgz4I6Y2xo0r72BRXlnyf7JFqrbEfELqRznMknM4eYPkQDfnsBP7VN5Bu herAS8So3wC7EfVyFtHki0yxF_kdlJ96XNcRxLw5Qk WGUE3bL8d4PpIn1iiMs7MriSMe8lTu6Flj7v3MfeUwFsw8qDWXoF dvr_xXghcjO0jU9MIOgc_5NCDxij2 PIzW69QzpxRqjfN1H4aAaXYyKw==-GxQAAKRdxtretCCEFCKK5DqwG4Nvu_EA-e

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to generic.external.zlb.scl3.mozilla.com  (63.245.213.12:443)

TCP (HTTP):
Connects to ec2-52-50-196-247.eu-west-1.compute.amazonaws.com  (52.50.196.247:80)

TCP (HTTP):
Connects to 10gbps.io  (185.59.222.146:80)

TCP (HTTP):
Connects to ec2-52-214-247-42.eu-west-1.compute.amazonaws.com  (52.214.247.42:80)

TCP (HTTP):
Connects to server-54-192-130-4.ams50.r.cloudfront.net  (54.192.130.4:80)

TCP (HTTP):
Connects to server-54-192-130-243.ams50.r.cloudfront.net  (54.192.130.243:80)

TCP (HTTP):
Connects to s3-1-w.amazonaws.com  (54.231.114.50:80)

TCP (HTTP):
Connects to ec2-54-154-109-8.eu-west-1.compute.amazonaws.com  (54.154.109.8:80)

TCP (HTTP):
Connects to ec2-52-208-40-227.eu-west-1.compute.amazonaws.com  (52.208.40.227:80)

TCP (HTTP):
Connects to ec2-176-34-130-130.eu-west-1.compute.amazonaws.com  (176.34.130.130:80)

TCP (HTTP SSL):
Connects to a104-124-109-59.deploy.static.akamaitechnologies.com  (104.124.109.59:443)

TCP (HTTP):
Connects to server-54-192-203-89.fra50.r.cloudfront.net  (54.192.203.89:80)

TCP (HTTP):
Connects to server-52-85-83-156.lax1.r.cloudfront.net  (52.85.83.156:80)

TCP (HTTP):
Connects to ec2-54-154-229-88.eu-west-1.compute.amazonaws.com  (54.154.229.88:80)

TCP (HTTP):
Connects to ec2-54-154-190-87.eu-west-1.compute.amazonaws.com  (54.154.190.87:80)

TCP (HTTP):
Connects to ec2-52-39-235-174.us-west-2.compute.amazonaws.com  (52.39.235.174:80)

TCP (HTTP):
Connects to ec2-52-30-150-214.eu-west-1.compute.amazonaws.com  (52.30.150.214:80)

Remove internet-explorer_11.0.exe - Powered by Reason Core Security